Lucene search

K
ibmIBMF06887354DDD94FE99CB5726F22BA14A5150601047429290A863F8F70CF6B6E5
HistoryFeb 19, 2021 - 2:03 p.m.

Security Bulletin: A vulnerability in Bouncy Castle affects IBM Rational Performance Tester (CVE-2020-26939)

2021-02-1914:03:49
www.ibm.com
14

0.001 Low

EPSS

Percentile

36.2%

Summary

IBM Rational Performance Tester is vulnerable to error inputs in OAEPEncoding, potentially allowing a remote attacker to exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.

Vulnerability Details

CVEID:CVE-2020-26939
**DESCRIPTION:**Legion of the Bouncy Castle BC and Legion of the Bouncy Castle BC-FJA could allow a remote attacker to obtain sensitive information, caused by observable differences in behavior to rrror inputs in org.bouncycastle.crypto.encodings.OAEPEncoding. By using the OAEP Decoder to send invalid ciphertext that decrypts to a short payload, a remote attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191108 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
RPT 9.5
RPT 10.0

Remediation/Fixes

Upgrading to version 10.1.2 is strongly recommended.

Product VRMF APAR Remediation/First Fix
RPT 9.5 None <https://download4.boulder.ibm.com/sar/CMA/RAA/09ht2/0/PSIRT-28248-9.5.0.0-ifix.zip&gt;
RPT 10.0 None <https://download4.boulder.ibm.com/sar/CMA/RAA/09ht1/1/PSIRT-28248-10.0.2.1-ifix.zip&gt;

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

36.2%

Related for F06887354DDD94FE99CB5726F22BA14A5150601047429290A863F8F70CF6B6E5